VulnSea

nezhahq has 12 CVEs on record. Disclosures have slowed: 2 in the last 90 days after 10 in the 90 before. The busiest recent month was June 2026 with 10. The median CVSS is 6.9 (medium), with 3 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.9
Publish → KEV
—
Last 90 days
2 prev 10

Products

  • github.com/nezhahq/nezha 12
12
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

nezhahq vulnerabilities

CVEs affecting nezhahq, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

GHSA-rf68-8gjr-36q7Low
1w ago

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty

▾ Sunlitnezhahq · github.com/nezhahq/nezhavia OSV
CVE-2026-62283Critical· 9.9
1mo ago

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_strea…

▾ Midnightnezhahq · github.com/nezhahq/nezhaEPSS 0.55%via NVD
GHSA-q6xx-5vr8-p898Critical· 9.9
3mo ago

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

▾ Midnightnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-53520Medium· 6.5
3mo ago

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.40%via GHSA
CVE-2026-53521Medium· 6.4
3mo ago

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.31%via GHSA
CVE-2026-53519Critical· 9.1PoC
3mo ago

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key

▾ Abyssalnezhahq · github.com/nezhahq/nezhaEPSS 2.3%via GHSA
CVE-2026-53522Medium· 6.5
3mo ago

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.41%via GHSA
CVE-2026-53523Medium· 6.8
3mo ago

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.32%via GHSA
GHSA-ww5p-j6cj-6mqqMedium
3mo ago

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API

▾ Sunlitnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-49396High· 7.1
3mo ago

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

▾ Twilightnezhahq · github.com/nezhahq/nezhaEPSS 0.17%via GHSA
CVE-2026-49397Medium· 5.3
3mo ago

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.34%via GHSA
CVE-2026-48119High· 7.1
3mo ago

Nezha's authenticated agents can forge service-monitor results for other users' services

Nezha's authenticated agents can forge service-monitor results for other users' services

▾ Twilightnezhahq · github.com/nezhahq/nezhaEPSS 0.37%via OSV
nezhahq vulnerabilities (CVEs) · VulnSea